2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18266 | MEDIUM | 5.4 | — | Jul 29, 2026 | Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose ... |
| CVE-2026-16553 | MEDIUM | 5.4 | 0.3% | Jul 29, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2... |
| CVE-2026-15831 | MEDIUM | 4.3 | 0.2% | Jul 29, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that u... |
| CVE-2026-15077 | MEDIUM | 4.3 | 0.2% | Jul 29, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that u... |
| CVE-2026-14351 | MEDIUM | 4.3 | 0.3% | Jul 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19... |
| CVE-2026-14341 | MEDIUM | 4.9 | 0.3% | Jul 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 1... |
| CVE-2026-13113 | MEDIUM | 5.3 | 0.2% | Jul 29, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2... |
| CVE-2026-13346 | MEDIUM | 5.6 | 0.3% | Jul 29, 2026 | pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary lo... |
| CVE-2026-59920 | MEDIUM | 6.5 | 0.2% | Jul 29, 2026 | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina... |
| CVE-2026-59919 | MEDIUM | 5.5 | 0.1% | Jul 29, 2026 | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina... |
| CVE-2026-59900 | MEDIUM | 5.3 | 0.3% | Jul 29, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ... |
| CVE-2026-54705 | MEDIUM | 6.3 | 0.2% | Jul 29, 2026 | MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode conten... |
| CVE-2026-13723 | MEDIUM | 6.5 | 0.3% | Jul 29, 2026 | A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrar... |
| CVE-2026-20316 | MEDIUM | 5.3 | 0.8% | Jul 29, 2026 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti... |
| CVE-2026-18257 | MEDIUM | 5.6 | — | Jul 29, 2026 | Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a cert... |
| CVE-2026-16729 | MEDIUM | 6.5 | 0.2% | Jul 29, 2026 | undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before ... |
| CVE-2026-15144 | MEDIUM | 5.3 | 0.3% | Jul 29, 2026 | @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Bec... |
| CVE-2026-67193 | MEDIUM | 6.9 | 0.3% | Jul 29, 2026 | Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to... |
| CVE-2026-54082 | MEDIUM | 6.5 | 0.2% | Jul 29, 2026 | veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve... |
| CVE-2026-54081 | MEDIUM | 6.9 | 0.3% | Jul 29, 2026 | veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service... |
| CVE-2026-54080 | MEDIUM | 6.9 | 0.3% | Jul 29, 2026 | veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service... |
| CVE-2026-50558 | MEDIUM | 5.9 | — | Jul 29, 2026 | Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix d... |
| CVE-2026-17550 | MEDIUM | 5.5 | 0.1% | Jul 29, 2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili... |
| CVE-2026-66724 | MEDIUM | 5.3 | 0.3% | Jul 29, 2026 | MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob u... |
| CVE-2026-54663 | MEDIUM | 6.1 | 0.2% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now